CVE-2025-49198: Poor quality of randomness in authorization tokens
Published Jun 12, 2025
·Updated
The Media Server’s authorization tokens have a poor quality of randomness. An attacker may be able to guess the token of an active user by computing plausible tokens.
Affected Software
1 affected component
SICK Media Server
Event History
Jun 12, 2025
CVE Published
via MITRE·02:24 PM
Data Sourced
via MITRE·02:24 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·03:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-49198?
CVE-2025-49198 has a severity score of 7.5, which is categorized as high.
2
How do I fix CVE-2025-49198?
To mitigate CVE-2025-49198, it is recommended to use a stronger and more random method for generating authorization tokens.
3
What is the potential impact of CVE-2025-49198?
CVE-2025-49198 may allow an attacker to guess authorization tokens, potentially compromising active user sessions.
4
Which software is affected by CVE-2025-49198?
CVE-2025-49198 affects the SICK Media Server.
5
When was CVE-2025-49198 published?
CVE-2025-49198 was published on June 12, 2025.